8.7

CVSS4.0

CVE-2015-10145 - Gargoyle 1.5.x Authenticated OS Command Execution via run_commands.sh

Gargoyle router management utility versions 1.5.x contain an authenticated OS command execution vulnerability in /utility/run_commands.sh. The application fails to properly restrict or validate input supplied via the 'commands' parameter, allowing an authenticated attacker to execute arbitrary shel…

πŸ“… Published: Dec. 31, 2025, 8:48 p.m. πŸ”„ Last Modified: March 23, 2026, 3:43 p.m.

7.1

CVSS3.1

CVE-2025-53235 - WordPress Easy Social plugin <= 1.3 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in osuthorpe Easy Social easy-social-media allows Reflected XSS.This issue affects Easy Social: from n/a through <= 1.3.

πŸ“… Published: Dec. 31, 2025, 8:11 p.m. πŸ”„ Last Modified: April 23, 2026, 3:32 p.m.

7.1

CVSS3.1

CVE-2025-52739 - WordPress Sala theme <= 1.1.3 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in uxper Sala allows Reflected XSS.This issue affects Sala: from n/a through 1.1.3.

πŸ“… Published: Dec. 31, 2025, 8:10 p.m. πŸ”„ Last Modified: April 28, 2026, 4:13 p.m.

7.1

CVSS3.1

CVE-2025-50053 - WordPress Blappsta Mobile App Plugin – Your native, mobile iPhone App and Android App Plugin <= 0.8…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nebelhorn Blappsta Mobile App Plugin – Your native, mobile iPhone App and Android App yournewsapp allows Reflected XSS.This issue affects Blappsta Mobile App Plugin – Your native, mobile iPhone App…

πŸ“… Published: Dec. 31, 2025, 8:09 p.m. πŸ”„ Last Modified: April 28, 2026, 4:13 p.m.

7.1

CVSS3.1

CVE-2025-47566 - WordPress ZoomSounds plugin <= 6.91 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ZoomSounds allows Reflected XSS.This issue affects ZoomSounds: from n/a through 6.91.

πŸ“… Published: Dec. 31, 2025, 8:07 p.m. πŸ”„ Last Modified: April 28, 2026, 4:12 p.m.

7.1

CVSS3.1

CVE-2025-31054 - WordPress Bloggie theme <= 2.0.8 - Cross Site Scripting (XSS) Vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in Themefy Bloggie allows Reflected XSS.This issue affects Bloggie: from n/a through 2.0.8.

πŸ“… Published: Dec. 31, 2025, 8:05 p.m. πŸ”„ Last Modified: April 28, 2026, 4:12 p.m.

8.5

CVSS3.1

CVE-2025-30628 - WordPress Amazon Affiliates Addon for WPBakery Page Builder (formerly Visual Composer) plugin <= 1.…

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team Amazon Affiliates Addon for WPBakery Page Builder (formerly Visual Composer) allows SQL Injection.This issue affects Amazon Affiliates Addon for WPBakery Page Builder (formerly Visual Compo…

πŸ“… Published: Dec. 31, 2025, 8:03 p.m. πŸ”„ Last Modified: April 28, 2026, 4:11 p.m.

0.0

CVE-2025-28973 - WordPress Pro Bulk Watermark Plugin for WordPress <= 2.0 - Path Traversal Vulnerability

Path Traversal: '.../...//' vulnerability in AA-Team Pro Bulk Watermark Plugin for WordPress pro-watermark allows Path Traversal.This issue affects Pro Bulk Watermark Plugin for WordPress: from n/a through <= 2.0.

πŸ“… Published: Dec. 31, 2025, 8:02 p.m. πŸ”„ Last Modified: April 23, 2026, 3:26 p.m.

8.5

CVSS3.1

CVE-2025-28949 - WordPress Mediabay - WordPress Media Library Folders <= 1.4 - SQL Injection Vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Codedraft Mediabay - WordPress Media Library Folders allows Blind SQL Injection.This issue affects Mediabay - WordPress Media Library Folders: from n/a through 1.4.

πŸ“… Published: Dec. 31, 2025, 8 p.m. πŸ”„ Last Modified: April 28, 2026, 4:11 p.m.

7.1

CVSS3.1

CVE-2025-23757 - WordPress ZD Scribd iPaper plugin <= 1.0 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Proloy Chakroborty ZD Scribd iPaper zd-scribd-ipaper allows Reflected XSS.This issue affects ZD Scribd iPaper: from n/a through <= 1.0.

πŸ“… Published: Dec. 31, 2025, 7:58 p.m. πŸ”„ Last Modified: April 23, 2026, 3:24 p.m.
Total resulsts: 347939
Page 2192 of 34,794
Β« previous page Β» next page
Filters